Controls you can hand to an examiner.
Every action tiered by what it changes, every decision logged and attributable, and business identity handled to the same standard as consumer.
Security you can verify.
Cotribute is SOC 2 Type 2 certified. The report and our security posture are available without a form in our Trust Center: trust.cotribute.com ↗
Security
Access controls, encryption in transit and at rest, and role-scoped, read-only data access with personally identifiable information masked by default.
Availability
Monitored uptime with real-time and historical status published publicly at status.cotribute.com ↗.
Confidentiality
Member and customer data is never sent to public AI models and never used to train shared models. Data boundaries are contractual and technical.
Certifications and partner validations
SOC 2 Type 2
Independently audited controls over security, availability, and confidentiality — not a point-in-time snapshot, but sustained operation over the audit period. Full report available in the due-diligence package.
FIS GKYC Certified
Certified against FIS's Global KYC program requirements for identity verification and compliance workflows.
Core partner certifications
Jack Henry VIP Partner, Corelation Preferred Partner, Banno Certified, and Fiserv AppMarket Partner — each program includes the vendor's own security and integration review of Cotribute.
Continuous transparency
Our Vanta-powered trust center publishes control status continuously, and status.cotribute.com shows real-time and historical uptime. No NDA required to look.
How decisions are made.
Every decision rule is deterministic
A deterministic rule returns the same outcome for the same inputs, every time. Re-run an application from six months ago against the rule set that was live that day and you get that day's answer back, not an approximation of it. That is what makes the decisioning auditable rather than merely logged — an examiner asking why an application was declined receives the rule that declined it, not a probability.
No model sits in the decision path. The AI growth agents recommend outreach and prepare work for your staff. They do not approve, decline or refer an application. The two systems are separate by design, which is why most of the model-risk questions that dominate AI vendor reviews do not apply to the decisioning here.
Where a third-party score is an input — synthetic identity, business fraud — the score comes from a named vendor and the rule that consumes it is yours. You set the threshold. The rule that fires is deterministic, and both the score and the rule are recorded against the application.
Every automated action is logged and attributable to a rule or a person, with seven-year retention and personally identifiable information masked by default.Current as of September 2026
What Cotribute does not decide
Worth stating plainly, because it narrows your review. Credit decisions and underwriting are made in your core or your loan origination system, not in Cotribute. The platform captures the application, runs eligibility, fraud and product qualification, and hands off. Adverse action, credit policy and underwriting model governance stay where they already sit, with the systems and the committees that already own them.
Cotribute is an origination layer. Credit decisioning and underwriting remain in the systems of record you already govern.Current as of September 2026
You decide what the rules are. Both sets.
Pre-screening — eligibility, charter or field-of-membership qualification, fraud screening, and the product qualification that decides who is offered what before a full application begins.
Fraud and decisioning — 70+ rules across device and geolocation signals, synthetic identity scoring, document verification with liveness, OFAC and PEP screening, and the approve, decline and refer thresholds.
Cotribute proposes a starting set from what we have seen work and tunes it with your team at implementation. After that the rules are yours to change and yours to approve. Every change is logged — what changed, who changed it and when — so a rule set can be reconstructed as it stood on any date.
CPM Federal Credit Union: −82% manual review effort via auto-decisioning, with +32% new accounts opened.Client-reported
What an examiner or a third-party risk reviewer gets.
Published without a form. The trust centre is Vanta-powered, so control status is live rather than an annual PDF that ages between audits.
| Item | What it covers |
|---|---|
| SOC 2 Type 2 | Independently audited controls operating over an audit period rather than at a point in time. Criteria in scope: Security, Availability and Confidentiality. |
| Control status | Published continuously through the Trust Center, not refreshed once a year |
| Uptime | Real-time and historical, at status.cotribute.com |
| Audit trail | Every automated action logged with seven-year retention, attributable to a rule or a person, PII masked by default |
| Rule change history | Every configuration change logged with what changed, who changed it and when |
| Model exposure | No member or customer data sent to public models, and none used to train shared models |
| Identity certification | FIS GKYC certified against its Global KYC program requirements |
| Core partner status | Jack Henry VIP Partner, Corelation Preferred Partner, Banno Certified, Fiserv AppMarket Partner |
| Subprocessors | Listed for third and fourth-party assessment |
→ Trust Center — live control status
Methodology note: SOC 2 Type 2 scope as published on the Cotribute Trust Center: Security, Availability and Confidentiality. Processing Integrity and Privacy are not within the current report scope. Request the report itself through the Trust Center for the audit period, the auditor and the full control listing.
Fraud and identity.
Rules you tune, running before the account exists
70+ configurable rules across device and geolocation signals, synthetic identity scoring, document verification with liveness, and OFAC and PEP screening. Tuned with your team rather than set by us, and applied before an account is created rather than after it is booked.
CPM Federal Credit Union: −82% manual review effort via auto-decisioning.Client-reported
Business held to the same standard
Secretary of State validation across all 50 states, beneficial ownership verified under FinCEN CDD, watchlist screening, and a business fraud score scored separately from consumer rules. → Business banking
Secretary of State validation across all 50 states, beneficial ownership verified under FinCEN CDD, and a business fraud score scored separately from your consumer rules.In production · September 2026
AI that recommends, never decides
Three AI growth agents recommend outreach and prepare work for your staff. Approval checkpoints are structural rather than optional, no agent takes an action outside the rules your institution configured and approved, data access is role-scoped and read-only, and removing someone from an account is never self-service.
Three AI growth agents in production since June 2025. SOC 2 Type 2 across Security, Availability and Confidentiality.Current as of September 2026
“Cotribute's decision intelligence and fraud detection capabilities have been a game changer for CPM. The fraud tools stop suspected fraudulent applications prior to account creation, eliminating the manual workload of the investigation.”
The due-diligence package
One request, everything your third-party risk review needs — typically the same week you ask.
SOC 2 Type 2 report
The full auditor's report, under NDA through the trust center.
Pre-filled vendor questionnaire
Standard due-diligence questionnaire answered in advance, so your team reviews instead of chasing.
Insurance certificates
Current certificates of insurance, including cyber coverage.
Questions we get
Is any part of the decision made by a model?
No. Every decision rule is deterministic — the same inputs return the same outcome, every time. Where a third-party score is an input, such as synthetic identity or business fraud, the score comes from a named vendor and the rule consuming it is yours: you set the threshold, and the rule that fires is deterministic and recorded.
Does Cotribute make credit decisions or underwrite?
No. Credit decisions and underwriting are made in your core or your loan origination system. Cotribute captures the application, runs eligibility, fraud and product qualification, and hands off. Adverse action, credit policy and underwriting model governance stay with the systems and committees that already own them.
Can we re-run a historical application and get the same answer?
Yes. Because the rules are deterministic and every configuration change is logged with what changed, who changed it and when, a rule set can be reconstructed as it stood on any date and the application re-run against it. That is the difference between decisioning that is auditable and decisioning that is merely logged.
Who can change a rule, and is the change recorded?
Your institution decides what the rules are, for pre-screening and for fraud and decisioning alike. Cotribute proposes a starting set and tunes it with your team at implementation; after that, changes are yours to make and approve. Every change is logged with what changed, who changed it and when.
Which SOC 2 criteria are in scope?
Security, Availability and Confidentiality, under a Type 2 report covering sustained operation over an audit period rather than a point-in-time snapshot. Processing Integrity and Privacy are not in the current scope. The Trust Center publishes control status continuously rather than annually.
Can we see your SOC 2 before a sales call?
Yes. The SOC 2 Type 2 and the wider security posture are published in the Trust Center without a form. Cotribute is also FIS GKYC certified, and the subprocessor list is available for your third and fourth-party assessment.
How do you satisfy CIP?
The required elements are captured in the flow, with OFAC and watchlist screening, customer due diligence and beneficial ownership collection for business accounts, and an audit trail that supports a SAR if one is needed.
How is fraud screening applied, and when?
Seventy or more configurable rules run before an account is created, covering device and geolocation signals, synthetic identity scoring, document verification with liveness, and OFAC and PEP screening. The rules are tuned with your team rather than set by Cotribute and applied to consumer and business separately.
How does business identity verification work?
Secretary of State validation runs across all fifty states, beneficial ownership is verified under FinCEN customer due diligence requirements, and a business fraud score is calculated separately from your consumer rules. Business applicants are held to the same standard as consumer, in the same flow.
Will the AI take actions on member accounts?
No. Every agent recommends and prepares; your staff and your configured rules decide. Approval checkpoints are structural rather than optional, there are no autonomous actions, no member data goes to public models, every action is logged and attributable, and removing someone from an account is never self-service.
What do we hand an examiner or a third-party risk review?
Deterministic decision rules that reproduce on demand, a rule change history showing what changed and who changed it, an audit trail with seven-year retention attributable to a rule or a person, the SOC 2 Type 2 report, and the fact that no model sits in the decision path. Note that the NCUA has issued no AI-specific rules, so the standard applied is your existing model and vendor risk framework.
Does automating decisions mean accepting more risk?
Not in the results reported. CPM Federal Credit Union reduced manual review effort by 82% through auto-decisioning while opening 32% more new accounts. The rules that decide are yours to tune, so the risk appetite encoded in them stays a decision your team makes.
